By Ray Birch
CARMEL, Ind.—Crooks are working hard to take advantage of new opportunities as financial institutions focus on helping Americans through the COVID-19 pandemic, and as a result fraud attacks have spiked to record levels, reports Allied Solutions.
Two crimes topping the charts: ATM cash-out schemes and payment app fraud, the company said.
Addressing ATM cash-out crimes, Ann Davidson, VP-risk consulting at Allied Solutions, emphasized CUs need to confirm that no one other than the employee who is designated to make changes, in a controlled setting, can change daily and transaction limits on ATMs.
“This new threat is where the fraudster will get in remotely—penetrate the software of the ATM—and remove the limits to make withdrawals unlimited and clean out all the cash from the ATM,” she said, adding this threat to cash machines has finally hit the U.S. after working its way through Europe.
“ATM cash-out is one of the biggest security threats we face right now,” continued Davidson. “There's been a big spike in these crimes.”
Once limits are removed, bands of thieves hit machines with stolen cards and make numerous withdrawals, often cleaning out an ATM’s cash entirely.
‘Like Going to a Casino’
“The bad guys come in remotely with malware and remove the daily withdrawal limits,” explained Davidson. “Then it’s like going to the casino; they clean out all of the cash from the machine.”
Davidson has seen reports where crooks have removed more than $400,000 from a single machine.
“There is a credit union in Colorado that got hit for $110,000 and the bank across the street got hit for $800,000. This crime began in Europe, and everyone in the U.S. kept saying it won’t make its way here,” said Davidson. “But now it has.”
Those two financial institutions would not have suffered huge losses had they put in place daily limits set in a “controlled setting,” according to Davidson. “You want a controlled setting in place where only certain people can change the limits. That way if anyone other than those people in the controlled setting attempt to change the ATM limits, the machine or machines shut down.”
‘Exactly What You Want’
Davidson said some financial institutions fear that having limits in place might limit the performance of the ATM network and lead to downtime, which affects service to members and customers.
“But you have to have these limits and have them set in a controlled setting,” reiterated Davidson. “The authorized person makes the request and the ATM processor has to authenticate that person before a change is made. That’s exactly what you want. More credit unions are recognizing this growing threat and are saying they are less concerned about a machine shutting down and impacting service and more concerned with stopping this crime.”
Davidson said the cash-out crime came to light in 2013 when more than $45 million in losses were reported from attacks that took place outside the U.S.
As is always the case with crooks, they exploit the weakest link, said Davidson.
“And right now, with this cash-out crime, the U.S. is the weakest link because many financial institutions don’t have the proper ATM controls in place,” said Davidson. “Right now, the criminals just keep coming back for more and more money from U.S. ATMs.”
Davidson advised credit unions to validate and confirm they have controlled settings in place on their ATMs to prevent changes to daily transaction and dollar limits, and have machines set to automatically shut down if a change to limits is made outside of the controlled setting.
Another Growing Crime
Meanwhile, credit unions need to be paying attention to another growing crime—payment app fraud, warned Davidson.
“You go out and sign up for payment apps like Zelle, Venmo or Cash App, for example. You enter your information and where you want your money pulled from—your 16-digit card number or your account number and routing number with your credit union. Very little information is needed to begin moving money,” said Davidson.
What is happening now is criminals are “phishing” that information, jumping on a payment app, and moving money out of individuals’ accounts before they even realize the money is gone.
“I spoke with a credit union that had 60 transactions in a 24-hour period on one member’s payment app account, and they had never even signed up for the app,” said Davidson.
The Best Defense
Once again, Davidson said the best defense against payment app fraud lies in setting daily dollar and number of transaction limits—velocity limits.
“You have to have velocity limits in place per account for these payment app transactions,” advised Davidson. “You have to limit how quickly and how frequently these transactions can happen in a day, and how many can happen in a day.”
Davidson said fraudsters are gaining payment app credentials via phishing scams and by reaching out to call centers.
“They call the call center and say they forgot their password to online banking,” said Davidson. “So the call center provides a temporary password and they text a secure code out, but it’s to the criminal’s number. With the secure code, the criminal gains access to online banking and can then reset the email and phone number. Then they clean out the legitimate individual’s account.”
